bickford · AI Workflow Evidence Pack
Questions
What exactly do I get?
A PDF report (about 16 pages for a typical export) with an executive summary, a workflow map, a gap matrix against ISO/IEC 42001, the NIST AI RMF 1.0 and the EU AI Act, a risk-ranked findings table across 24 checks (9 measured from your logs, 14 from your answers, 1 from your retention policy), a 30-day remediation plan sized to your capacity, and a ledger appendix. Alongside it: findings.json (the same findings as data), ledger.jsonl (every decision record replayed into a SHA-256 hash chain) and report.html. The sample report is the exact output for a synthetic insurer.
Is this an audit?
No. It is a self-assessment generated by software from what you submit. No person reviews it. It is not an audit opinion, a certification, or legal advice, and it does not make you compliant with anything. It gives you a written, evidence-based picture of one AI workflow that you can put in front of your own risk committee, auditor or examiner, and a plan to close the gaps.
Who is it for?
Organizations that use AI or predictive models in decisions about people and have been asked, or expect to be asked, to show how those decisions were governed: insurers under the Pennsylvania Insurance Department's Notice 2024-04 and the NAIC model bulletin adopted in other states, lenders, health plans, and the audit and compliance teams that serve them. If a vendor's tool makes or shapes the decision, you are still the one asked for the evidence.
What does "Not evidenced" mean?
Your answers or logs did not show it. It is scored like a gap because an examiner treats it the same way. If you have the evidence, answer "yes" with a one-line description and the report records it.
What do the logs need to contain?
One record per decision, as CSV or JSONL. The more of these fields it has, the more checks can be measured: decision ID, timestamp, model name, model version, input reference, output, score, amount, policy checks, reviewer, override, override reason, reason codes. Columns can be named anything; you map them on the form. Fields that are missing are reported as missing, which is itself a finding.
Do I have to send personal data?
No, and please don't. Export references or hashes, not names, addresses, dates of birth or health details. The report never needs them. See privacy and retention.
How long does it take?
The form takes about fifteen minutes. The run takes seconds to a minute. The delivery page updates on its own.
How do I verify the ledger?
Every line in ledger.jsonl contains the hash of the previous line. The delivery page prints a one-line Node command that recomputes the chain; if any record was changed, removed or reordered, it reports where.
What is the difference between the Readiness Check and the full pack?
The Readiness Check ($49) runs on your answers alone: the 15 practice and retention checks are scored, and the 9 checks that need decision records are reported as not measured, each with a note on what the full pack would prove. The full Evidence Pack ($750) adds the log export: those 9 checks are measured from your records, and you get the hash-chained ledger. Same report format, same 24 checks; the difference is evidence from data versus evidence from answers.
What does it cost, and what if it is not useful?
One fixed price per workflow, shown on the form, paid by card through Stripe. If it is not useful, reply to your Stripe receipt or email bickfordd@gmail.com with the order ID and you get a refund, no questions.
Can I run it again after fixing things?
Yes. Each run is a new order with the new export; comparing the two readiness scores is the simplest before-and-after evidence you can show.
Who built it?
Derek Bickford, Bickford Technologies, Philadelphia. The engine, its control mapping and its tests were built in 2026; every framework reference was checked against public sources and carries a verification date in the report.
Bickford Technologies · Philadelphia, PA